But the company warned that the cybercriminals behind the intrusion “may attempt to use brute force to guess your master password and decrypt the copies of vault data they took.”Toubba said that the cybercriminals also took vast reams of customer data, including names, email addresses, phone numbers and some billing information.Password managers are overwhelmingly a good thing to use for storing your passwords, which should all be long, complex and unique to each site or service.But security incidents like this are a reminder that not all password managers are created equal and can be attacked, or compromised, in different ways.In a rare shituation (not a typo) like this — which we spelled out in our parsing of LastPass’s data breach notice — if a bad actor has access to customers’ encrypted password vaults, “all they would need is a victim’s master password.” An exposed or compromised password vault is only as strong as the encryption — and the password — used to scramble it.If you think that your LastPass password vault could be compromised — such as if your master password is weak or you’ve used it elsewhere — you should begin changing the passwords stored in your LastPass vault."